Hackers Used WhatsApp 0-Day Flaw to Secretly Install Spyware On Phones
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-3568 | Buffer Overflow RCE in WhatsApp VoIP Stack via Crafted RTCP Packets A buffer overflow (CWE-122) in the VoIP telephony stack of WhatsApp allowed a remote attacker to achieve remote code execution on a target device by sending a specially crafted series of RTCP packets to the victim's phone number. Because the flaw resided in the call-handling stack of the core app, an attacker who could reach the target's phone number over the network could gain arbitrary code execution on the device. All WhatsApp users at the time of disclosure were potentially exposed, since the vulnerable component shipped in the mainstream Meta Platforms (then Facebook) product rather than an optional add-on. The vulnerability was added to CISA's Known Exploited Vulnerability catalog on 2022-04-19, indicating confirmed real-world exploitation, and its EPSS score of 39.2% (99th percentile) signals a high likelihood of continued exploitation; no public proof-of-concept is known. It was remediated in vendor updates issued in 2019 and is widely associated with targeted espionage use (notably Pegasus spyware deployments). Do: Update WhatsApp on all mobile devices to the latest vendor release, per the CISA KEV required action; inventory your mobile fleet for outdated 2019-era builds and verify current app versions. Prioritize high-value targets (executives, journalists, government personnel) given the vulnerability's confirmed in-the-wild exploitation in espionage campaigns. No public PoC is known, but the flaw is remotely exploitable via network packets to a phone number, so treat patching as urgent. | 9.8 | 30% | KEV |
| mass≈1.5–2 billion users (effectively the entire global WhatsApp user base at the time of disclosure) |
Full article455 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalMay 14, 2019
Whatsapp has recently patched a severe vulnerability that was being exploited by attackers to remotely install surveillance malware on a few "selected" smartphones by simply calling the targeted phone numbers over Whatsapp audio call.
Discovered, weaponized and then sold by the Israeli company NSO Group that produces the most advanced mobile spyware on the planet, the WhatsApp exploit installs Pegasus spyware on to Android and iOS devices.
According to an advisory published by Facebook, a buffer overflow vulnerability in WhatsApp VOIP stack allows remote attackers to execute arbitrary code on target phones by sending a specially crafted series of SRTCP packets.
Apparently, the vulnerability, identified as CVE-2019-3568, can successfully be exploited to install the spyware and steal data from a targeted Android phone or iPhone by merely placing a WhatsApp call, even when the call is not answered.
Also, the victim would not be able to find out about the intrusion afterward as the spyware erases the incoming call information from the logs to operate stealthily.
Though the exact number of targeted WhatsApp users is not yet known, WhatsApp engineers did confirm that only a "select number" of users were targeted by the NSO Group spyware using this vulnerability.
Meanwhile, Citizen Lab, a watchdog group at the University of Toronto which is investigating NSO Group's activities, believe the vulnerability was used to attack a UK-based human rights lawyer as recently as Sunday.
NSO Group's Pegasus spyware allows attackers to access an incredible amount of data from victims' smartphones remotely, including their text messages, emails, WhatsApp messages, contact details, calls record, location, microphone, and camera—all without the victims' knowledge.
The nasty spyware has previously been used against human rights activists and journalists, from Mexico to the United Arab Emirates, and Amnesty International staffers in Saudi Arabia and another Saudi human rights defender based abroad earlier last year.
The vulnerability affects all except the latest version of WhatsApp on iOS and Android, meaning the flaw affected all 1.5 billion people using WhatsApp until yesterday when Facebook finally patched the issue.
"The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15," Facebook says.
WhatsApp engineers discovered the vulnerability earlier this month and alerted the Department of Justice of the issue. They encourage users on both iOS and Android to update their apps to the latest version of the popular messaging app as soon as possible.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/05/hack-whatsapp-vulnerability.html